<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Prime Mover (&lt; 2.2.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/prime-mover--2.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 18:13:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/prime-mover--2.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Zip Slip Vulnerability in Prime Mover WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-prime-mover-zip-slip/</link><pubDate>Thu, 01 Oct 2026 18:13:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-prime-mover-zip-slip/</guid><description>The Prime Mover WordPress plugin before version 2.2.1 is vulnerable to Zip Slip, allowing authenticated administrators to perform arbitrary file writes via path traversal during ZIP archive extraction.</description><content:encoded><![CDATA[<p>The Prime Mover plugin for WordPress, prior to version 2.2.1, contains a Zip Slip vulnerability residing in its migration ZIP import functionality. This vulnerability occurs because the plugin fails to properly sanitize the filenames of entries within uploaded ZIP archives during the extraction process. Specifically, the functions computeExtractionParameters() and resumableZipExtractor(), located within utilities/PrimeMoverSystemCheckUtilities.php, process entry names containing path traversal sequences. An authenticated administrator can craft a malicious ZIP archive containing entries with relative path components (e.g., ../) to force the application to extract files outside of the intended directory. This permits an attacker to overwrite critical system or application files, potentially leading to remote code execution if the environment is configured to interpret or execute the attacker-controlled files.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for arbitrary file write and potential remote code execution on the affected WordPress site. Successful exploitation requires an authenticated administrative account, limiting the initial vector to users with existing high-privilege access. If exploited, an attacker could gain full control over the web application environment by overwriting configuration files or injecting web shells into reachable directories.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Prime Mover plugin to version 2.2.1 or later to remediate the Zip Slip path traversal vulnerability (CVE-2026-101888).</p>
<h2 id="reference">Reference</h2>
<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-101888">https://nvd.nist.gov/vuln/detail/CVE-2026-101888</a></li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>